PT-2026-63392 · Nlnet · Unbound
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
NLnet Labs Unbound versions prior to 1.25.2
Description
A heap buffer overflow occurs when the validator builds the canonical RDATA form for an RRSIG-covered PX, RP, MINFO, or SOA RRset. The system computes the address of the second embedded domain name and passes it to the
query dname tolower() function without verifying if a second name exists in the RDATA. An attacker operating a DNSSEC-signed authoritative server can provide a record missing the second domain name, causing query dname tolower() to read stale bytes in the env->scratch buffer. If the msg-buffer-size is lower than the default, this process can read past the end of the heap allocation.Recommendations
Update to version 1.25.2 or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unbound